Water Utilities Under Siege: Rand Water Discloses Cyberattack as US Water Systems Report Intrusions

Water Utilities Under Siege: Rand Water Discloses Cyberattack as US Water Systems Report Intrusions

Water Utilities Under Siege: Rand Water Discloses Cyberattack as US Water Systems Report Intrusions

Water utilities on two continents are dealing with cyberattacks. On Thursday, September 3, 2026, Rand Water — South Africa's biggest bulk water utility — disclosed that it is responding to a cybersecurity incident affecting certain information technology systems. The company said the impact on operations has been minimal, and that its critical operational activities, including water treatment processes, water quality control systems, and bulk water supply operations, remain fully operational and continue to function normally.

Rand Water's treasury operations continue to run through its disaster recovery environment, and the utility says there is no indication of missing funds or impaired ability to service its listed debt obligations. The nature of the incident — including the suspected attackers and the type of attack — was not disclosed. Notably, the disclosure came through a note to holders of its listed debt securities on the JSE's debt board; most public entities carry no equivalent obligation, which is why incidents elsewhere tend to surface through leaks, auditor findings, or the attackers themselves.

Part of a Global Pattern

The same week, two municipal water systems in New Jersey disclosed that they had been targeted in cyberattacks, with Iran identified as the prime suspect by sources speaking to ABC News. In New Hampshire, water suppliers described cyber threats as an immense and global challenge. U.S. officials frame the problem as national in scope but local in responsibility — water systems are thousands of small operators, most without dedicated security teams.

The South African context is equally sobering. The auditor-general's 2026 report on government cyber defences singled out the South African Bureau of Standards, whose systems were fully encrypted in a November 2024 ransomware attack that shut down its business applications — with outdated systems, weak password policies, poor access controls, and an untested disaster recovery plan cited as contributing factors. Check Point's African Perspectives report found that 41% of the world's major ransomware attacks target African organisations, despite the continent's comparatively thin digital infrastructure.

What Should You Do?

  1. Inventory internet-facing services. Billing portals, customer web apps, remote management interfaces, and vendor access points are the attack surface — know what is exposed and why.
  2. Enforce MFA on remote access. Weak passwords and untested recovery paths were recurring findings in both public and private utility incidents.
  3. Segment IT from OT. Rand Water's water treatment and quality control continued normally because operational systems were not the blast radius — that separation is the lesson worth copying.
  4. Test disaster recovery, don't just document it. The SABS incident showed that an untested DR plan is indistinguishable from no plan.

The WAF Angle

Utilities rarely get hacked through exotic OT exploits — the practical entry points are the same web applications, remote-access portals, and file-upload forms everyone else has. A WAF in front of customer portals and administrative interfaces, combined with strict access control and monitoring, closes the most common initial-access paths before they reach operational networks. And as the Rand Water case shows, detection matters as much as prevention: the incident was contained, operations continued, and disclosure happened because obligations and plans existed. For organizations with no security team, a managed WAF plus basic exposure management is the highest-leverage combination available.

Sources